Privacy & Data Collection Policy
We built Skoolit for parents who are already overwhelmed. So we wrote this policy the way we'd want to read one ourselves — in plain language, with no hidden surprises.
The short version: we collect only what we need to run the service, we never sell your data or your children's data, and you stay in control. Everything below explains exactly how that works.
If you have questions, email us at [email protected].
1. Who We Are and How to Reach Us
Skoolit, Inc. ("Skoolit," "we," "us," or "our") operates the Skoolit platform, accessible at getskoolit.com and via the Skoolit progressive web application (the "Service"). We are the data controller responsible for personal information collected through the Service.
Privacy contact: [email protected]
Mailing address: United States (mailing address to be added at incorporation)
We will respond to all privacy-related inquiries within 30 days of receipt.
2. Scope of This Policy
This Privacy Policy applies to:
- All information you provide when creating a Skoolit account
- All information processed when you connect your email and calendar accounts
- Information about children added to your account
- Information collected automatically when you use the Service
- Communications between you and Skoolit
This policy does not apply to third-party services you connect to Skoolit, including Google, Apple, and Microsoft. Your interactions with those services are governed by their respective privacy policies.
3. Information We Collect
3.1 Information You Provide Directly
- Account information. When you register, we collect your name, email address, and password (stored as a secure hash — we never store your plain-text password).
- Child profile information. For each child you add, we collect their name, grade level, school name, school state, school district (optional), and homeroom teacher(s) (optional). This information is used solely to personalize the Service for your family.
- Payment information. We collect billing-related information necessary to process your subscription. Payment card details are collected and stored exclusively by Stripe, our payment processor. Skoolit stores only a Stripe customer ID and subscription status — never your full card details.
- Monitored sender configuration. You provide us with the email domains and individual sender addresses you want Skoolit to monitor. We store this list to operate the monitoring service.
- Uploaded documents. If you upload physical documents (such as paper flyers or printed schedules) for processing, we store those files and the information extracted from them.
- Communications with us. If you contact our support team, we retain records of those communications to resolve your issue and improve the Service.
3.2 Information We Process From Your Connected Accounts
- Email content from monitored senders. With your OAuth authorization, we access emails from the specific senders and domains you designate. We process the content of those emails through our AI pipeline to extract events, deadlines, action items, and other relevant information. We do not access, read, index, or store emails from senders outside your monitored list.
- 30-day backfill. When you first connect an email account (or add a new monitored sender), we process the prior 30 days of emails from your authorized senders. This backfill runs once and does not expand over time.
- Calendar data. With your OAuth authorization, we create, update, and delete calendar events in dedicated sub-calendars within your connected calendar account. We may read existing calendar event data solely to detect scheduling conflicts. We do not store the content of calendar events we did not create.
3.3 Information Collected Automatically
- Usage data. We collect information about how you interact with the Service, including features you use, screens you view, actions you take, and session duration.
- Device and connection information. We collect your device type, operating system, browser type and version, IP address, and general location (derived from IP address — not precise GPS location).
- Push notification tokens. If you install the Skoolit PWA and enable push notifications, we collect a push notification token to deliver alerts to you.
- Cookies and similar technologies. We use session cookies and local storage to keep you logged in and maintain your preferences. We do not use third-party advertising cookies or tracking pixels.
4. Children's Information
4.1 Nature of Children's Data
Skoolit stores and processes information about children under the age of 18, including children under the age of 13. This information is provided and authorized exclusively by a parent or legal guardian who operates the account. Children do not create accounts on Skoolit and do not interact with the Service directly.
4.2 COPPA Compliance
We comply with the Children's Online Privacy Protection Act ("COPPA"). We collect information about children under 13 only with the verifiable consent of a parent or legal guardian. We do not:
- Condition participation in the Service on a child providing more information than is reasonably necessary
- Use children's personal information for targeted advertising
- Share children's personal information with third parties for commercial purposes
- Allow children to create accounts or interact with the Service independently
4.3 FERPA Acknowledgment
Information we process may include student education records as defined under the Family Educational Rights and Privacy Act ("FERPA"). By connecting your email account and authorizing us to process school-related communications, you, as the parent or legal guardian, are directing us to receive and process education records on your behalf. We act as a service provider processing these records under your direction. We do not use education records for any purpose other than providing the Service to you.
4.4 Parental Rights
As the parent or legal guardian, you have the right to:
- Review all information stored about your children by contacting [email protected]
- Request correction of inaccurate information about your children
- Request deletion of your children's information at any time
- Revoke your consent for collection of your children's information by deleting your account
5. How We Use Your Information
We use the information we collect for the following purposes:
- Providing the Service. Processing your authorized emails to extract events, deadlines, and action items; creating and updating calendar events; delivering your daily digest and urgent alerts.
- Personalizing your experience. Associating extracted information with the correct child, applying your calendar preferences and notification settings.
- Improving accuracy. Using feedback and corrections you provide as labeled training signals to improve our AI pipeline's extraction accuracy.
- Security and fraud prevention. Detecting and preventing unauthorized access, abuse, or fraudulent activity.
- Communications. Sending transactional emails, responding to support requests, and notifying you of material changes to these policies.
- Legal compliance. Complying with applicable laws, regulations, and legal processes.
We do not use your information for targeted or behavioral advertising, selling or renting your data to third parties, building profiles of your children for any purpose other than operating the Service, or training general-purpose AI models.
6. How We Share Your Information
We do not sell, rent, or trade your personal information or your children's information to any third party.
6.1 Service Providers
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Anthropic | AI processing (email classification, extraction, summarization) | Email content from monitored senders; child profile context |
| Stripe | Payment processing and subscription management | Name, email, billing information |
| Cloud hosting (AWS / GCP) | Infrastructure and data storage | All account data (stored encrypted) |
| SendGrid / Postmark | Transactional email delivery | Email address, digest content |
| Analytics provider | Usage analytics and product improvement | Anonymized usage data |
6.2 Co-Parents and Caregivers You Authorize
If you invite a co-parent to link to your account, they will have access to your family's digest, calendar, and child profile information. If you invite a caregiver, they will receive schedule-relevant notifications only. You control these sharing relationships and can revoke them at any time.
6.3 Legal Requirements
We may disclose your information if we believe in good faith that disclosure is necessary to comply with a legal obligation, protect rights or safety, or detect and prevent fraud. Where legally permitted, we will notify you before complying.
6.4 Business Transfers
If Skoolit is acquired or merges with another company, your information may be transferred as part of that transaction. We will notify you via email before your information becomes subject to a different privacy policy.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information (name, email) | Duration of active subscription + 90 days |
| Child profile information | Duration of active subscription + 90 days |
| Processed email content and extracted items | Duration of active subscription + 90 days |
| Uploaded documents | Duration of active subscription + 90 days |
| Payment records (Stripe) | As required by applicable law (typically 7 years) |
| Usage and analytics data | 24 months, then aggregated/anonymized |
| Support communications | 3 years from last interaction |
| AI correction feedback (anonymized) | Indefinitely, in anonymized/aggregated form |
8. Data Security
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest: All stored data is encrypted at rest using AES-256.
- OAuth token security: OAuth tokens are stored securely and never exposed in client-side code or URLs.
- Access controls: Access to production data is restricted to authorized personnel on a need-to-know basis.
- Security testing: We conduct periodic penetration testing and dependency audits.
- Incident response: We maintain an incident response plan and will notify you promptly in the event of a breach as required by applicable law.
If you believe your account has been compromised, please contact us immediately at [email protected].
9. Your Privacy Rights
9.1 Your Rights
- Right to access. You may request a copy of the personal information we hold about you and your children.
- Right to correction. You may request that we correct inaccurate or incomplete information.
- Right to deletion. You may request that we delete your personal information and your children's information. We will fulfill deletion requests within 30 days, except where retention is required by law.
- Right to data portability. You may request a machine-readable export of your personal data and the items extracted by the Service.
- Right to withdraw consent. Where we process your data based on consent, you may withdraw that consent at any time.
- Right to restrict processing. You may request that we restrict processing of your data in certain circumstances.
- Right to object. You may object to processing of your data for purposes beyond providing the core Service.
9.2 How to Exercise Your Rights
Contact us at [email protected] with a description of your request. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests.
9.3 California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act, including the right to know what personal information has been collected, the right to opt out of the sale of personal information (we do not sell personal information), and the right to non-discrimination for exercising your rights. Contact [email protected] to submit a California-specific privacy request.
9.4 Other U.S. State Privacy Laws
If you are a resident of a state with applicable consumer privacy laws (including Virginia, Colorado, Connecticut, or other states with enacted comprehensive privacy legislation), you may have additional rights consistent with those laws. Contact [email protected] to submit a request.
10. International Users
The Service is operated in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your home country. The Service is not currently marketed to or intended for users in the European Economic Area, United Kingdom, or Switzerland.
11. Cookies and Tracking Technologies
- Strictly necessary cookies. Required for the Service to function — they maintain your login session and authentication token. You cannot opt out of strictly necessary cookies while using the Service.
- Functional cookies. Remember your preferences (such as your digest delivery time and notification settings).
- Analytics cookies. We use first-party analytics to understand how the Service is used. We do not use third-party advertising networks or tracking pixels.
We do not use cookies for behavioral advertising, retargeting, or cross-site tracking. You may control cookie settings through your browser.
12. Third-Party Services and Links
We encourage you to review the privacy policies of: Google, Apple, Microsoft, Stripe, and Anthropic.
13. Changes to This Policy
When we make material changes, we will notify you by email and/or in-app notification at least 14 days before the changes take effect. Your continued use of the Service after the effective date of any material change constitutes your acceptance of the updated policy.
14. Contact Us
| Purpose | Contact |
|---|---|
| General privacy inquiries | [email protected] |
| Data deletion or access requests | [email protected] |
| Security concerns or incidents | [email protected] |
| Legal / regulatory matters | [email protected] |
We aim to respond to all privacy-related inquiries within 30 days.
© 2026 Skoolit, Inc. All rights reserved. · Terms of Service